moai-security-compliance

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The best-presented fragment aligns with its stated purpose of regulatory compliance tooling and demonstrates coherent data flows across classification, logging, retention, erasure, and evidence collection, plus optional Drata integration. Key risks include hardcoded retention values, potential cross-sink data exposure, and reliance on external services. With proper hardening (config-driven retention, per-sink masking, encryption, strict access control, and secure secret management), this design can be production-ready. Treat as a solid baseline with notable security review needed before deployment.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 2, 2026, 05:17 PM
Package URL
pkg:socket/skills-sh/jg-chalk-io%2FNora-LiveKit%2Fmoai-security-compliance%2F@b6fadbf9528d2840b790af5505aff487b564354c